Wizard Legal
DocumentationProduct guides and practical next steps
DocumentationSigning & execution

Signing & execution

Understand provider-backed signing availability

See when a provider-backed signing method can appear, how the secure hand-off works, and why an evidence record is not itself a provider-certificate verdict.

4 min readUpdated 6 August 2026

You can use the local-signature workflow for supported documents: draw, type, or upload an authorised PNG or JPEG signature image. Aadhaar, DSC, and other provider signing methods are unavailable until provider verification is complete.

Illustrative security boundary

Provider-backed signing hand-off

Configured eMudra / emSigner HTTPS destination

  1. 1

    Prepare on the server

    Create the attempt and opaque provider form fields after capability checks.

  2. 2

    POST in the same browser window

    Send encrypted fields to the approved HTTPS provider destination, not a query string.

  3. 3

    Complete the provider ceremony

    Aadhaar, OTP, DSC, or other provider inputs stay with the provider.

  4. 4

    Return and verify the artifact

    Record the callback and recover the artifact only through the deployed, tested path.

Availability boundary: this diagram explains the candidate hand-off only. The provider mode stays unavailable until the deployed account, gateway, callback, success/failure/cancel behaviour, multi-signer artifacts, and independent PDF certificate validation have passed vendor UAT.
Wizard Legal must not collect Aadhaar details, provider credentials, DSC PINs, or mobile OTPs in its own form. This diagram is not proof that a provider option is enabled for an account or deployment.

Example only · independent review required

Provider-signed PDF review sheet

Example completed provider-signed PDF · Provider-returned artifact

Bind the returned PDF to the signing attempt

Match the stored attempt, approved callback, provider transaction reference, intended document version, and signer route before relying on the file.

Release gate

Validate the PDF signature container and signer certificate

Use an independent verifier to inspect the CMS signature and certificate chain rather than only checking that a visual signature marker exists.

Release gate

Check signing-time, revocation, and timestamp policy

Apply the provider contract and the organisation's policy to signing time, revocation evidence, timestamp requirements, and any certificate-validity result.

Release gate

Review the surrounding execution record

Keep the final PDF with the provider result, envelope events, authority and formalities evidence; those questions are not settled by a certificate panel alone.

Release gate
No implied pass result: this is a review artifact, not a signed PDF, provider receipt, certificate chain, revocation result, timestamp result, or assertion that a provider method is enabled.
Keep the returned final PDF, provider transaction reference, verification output, and relevant envelope evidence together. Investigate a failed, missing, expired, or mismatched check before representing a provider-signed artifact as verified.

Check the available method in the workspace

  1. 1Create or open the signing request, then check the methods and status presented for that request rather than assuming an Aadhaar or DSC option is enabled.
  2. 2A configured provider gateway certificate is checked as a current RSA X.509 certificate before a provider method can appear. That setup check is separate from validating the signer certificate embedded in a completed PDF.
  3. 3If a provider-backed method is unavailable, use only a method that the workspace presents as available, or wait until the organisation has completed the required provider setup.
  4. 4Do not collect Aadhaar details, mobile OTPs, provider credentials, or a DSC PIN in a Wizard Legal form. Those belong only in the approved provider ceremony.

What happens when a provider method is enabled

After the signer chooses the enabled provider method, Wizard Legal asks its server to create the provider attempt. The browser receives a configured HTTPS destination and opaque encrypted form fields, then posts them in the same browser window to the provider. The provider—not Wizard Legal—runs its identity or OTP ceremony and returns through the approved callback route. The signer should not copy encrypted fields, provider credentials, or OTPs into an email or chat message.

Review the completed artifact and evidence carefully

The workspace can retain the completed document and product evidence. A product audit chain can show that stored events still match the recorded chain, but it is not a replacement for independent validation of a provider PDF signature, certificate chain, signing-time policy, revocation status, signer authority, or applicable execution formalities.